-
Notifications
You must be signed in to change notification settings - Fork 36
Open
Labels
Description
每日安全资讯(2026-01-13)
- paper - Last paper
- 奇安信攻防社区
- SecWiki News
- Private Feed for M09Ic
- bolucat released 202601121941 at bolucat/Archive
- anthropics released v2.1.5 at anthropics/claude-code
- usestrix released v0.6.0 at usestrix/strix
- Ridter starred yhy0/ChYing
- 4ra1n starred yhy0/ChYing
- mgeeky starred kleiton0x00/Proxy-DLL-Loads
- WAY29 starred obra/superpowers
- gh0stkey starred jenish-sojitra/JSAnalyzer
- CHYbeta starred router-for-me/Cli-Proxy-API-Management-Center
- lz520520 starred teest114514/chatlog_alpha
- niudaii starred lintsinghua/DeepAudit
- rabbitmask starred geekoe/workflow3
- gh0stkey starred snarktank/ralph
- gh0stkey contributed to WinMin/OpenReCopilot
- gh0stkey forked HACK-THE-WORLD/OpenReCopilot from WinMin/OpenReCopilot
- WAY29 starred 9001/copyparty
- gh0stkey starred Lil-House/Pyarmor-Static-Unpack-1shot
- LevelBlue Blog
- Recent Commits to cve:main
- Tenable Blog
- CXSECURITY Database RSS Feed - CXSecurity.com
- 嘶吼 RoarTalk – 网络安全行业综合服务平台,4hou.com
- 安全客-有思想的安全新媒体
- XML陷阱:Struts 2高危漏洞CVE-2025-68493致数据泄露
- “粉河豚”攻击行动:银行恶意软件Astaroth转战WhatsApp发起新型攻击
- CVE-2026-22184(CVSS 评分 9.3)zlib高危漏洞引发全球性缓冲区溢出风险
- 锈水木马崛起:泥水坑组织弃用PowerShell,改用高隐蔽性Rust植入程序
- 执法打击力度加大,2025年勒索软件攻击仍激增47%
- 泥水坑组织借助鱼叉式钓鱼,在中东多行业部署“锈水”远程访问木马
- 数据投毒:2026年新兴人工智能安全防护策略
- 印度以应对网络威胁为由要求审查智能手机源代码
- NRF 2026:谷歌云推出零售业专属AI创新成果,赋能零售数字化转型
- 高危漏洞CVE-2025-68637:Apache Uniffle存在严重缺陷,致集群面临窃听风险
- Doonsec's feed
- 注意:境外未知组织正发起污染Ai大模型数据集计划
- 【转载】格陵兰岛是如何陷落的
- 【培训】第16期开源情报能力培训班1月北京开班
- 聊聊 “vibe writing” ,关于AI痕迹过重的文章就得琢磨一下是否有看下去的必要
- CrowdStrike宣布7.5亿美元现金收购身份安全初创公司SGNL
- 易忽视的敏感信息泄露
- 承影(ChYing):三年磨一剑,一个安全人的开源梦
- 【工具分享】最强免费开源取证工具箱合集
- 辛辛苦苦卖命,给公司裁员省了150多万,替公司裁了将近200人之后我自己被裁了。干完活就把我裁了,就是现实版 “狡兔死走狗烹”。
- 继续唠股票
- 死了么APP实则是用户智商检测仪。
- 网络安全企业疯狂裁人的终极目标是什么?
- 获取目标Telegram的真实IP
- Ralph Loop 的前世今生
- Deepseek越狱? 利用MoE “物理缺陷”越狱
- CVE-2025-68428_PoC
- 擦除与重生:Windows 系统下删除文件如何实现 LPE(持久化文件执行)
- HexStrike AI自动渗透测试平台搭建
- 每日课程更新
- [LLMSC@FSE] 第二届大模型供应链研讨会征稿通知
- 准备组织AI安全线下技术沙龙
- 不会逆向也能快速破解加解密爽挣两千大洋
- 宣传一下
- 死了么APP创始人吕同学河南人、新华电脑学院毕业
- 命令与控制(C2)的演进:从中心化到链上(On-Chain)
- 2026年1月13日A股市场预测
- 2025年度收官 | 知其安邀您共启成长图鉴!
- 【大话工控安全】工业控制系统行业知识:电力行业通信安全标准IEC62351(GB/T 25320)-PART11
- 人在海外,如何使用国内的网络环境?一个国内服务器即可搭建一个回国线路,在别国也能使用国内网络和APP
- 今日热点(国际)
- 今日热点(国内)
- ValleyRAT_S2攻击组织以部署隐形恶意软件并提取财务信息
- 一、使用ENSP模拟器搭建小型局域网
- 二、使用HCL模拟器搭建小型局域网
- 三、如何使用PPPOE拨号上网?
- OSCP/OSEP一对一私教直通车:协议保障,直通高级渗透测试专家
- 死了么APP创始人压力巨大:各路大佬纷纷加我、彻夜长谈
- 27岁天才腾讯科学家首秀?内容没营养被群嘲?
- 【AI安全】Deepseek越狱? 利用MoE 架构的“物理缺陷”实施越狱
- CTF自动化AWD工具 - AWD-H1M-PRO
- 如何将 AI 真正融入现代 SOC 工作流
- 今日分享|GBT 45279-2025 IPv4IPv6网络安全防护技术规范 第1部分:IP承载网
- BreachForums黑客攻击导致论坛数据库泄露,32.4万个账户信息暴露。
- CVE-2026-22184 (CVSS 9.3):zlib 严重漏洞导致全局缓冲区溢出
- 【接口漏洞第五章第一节】当API“过度热心”:批量赋值漏洞的狩猎笔记
- 四川天府银行发布2025数智化转型成果,AI贯穿全流程
- AI快讯:谷歌推“通用商务协议”UCP助力AI购物,蚂蚁国际参与试点
- 拟选1家!南京银行AI服务管理系统建设项目
- 杀猪盘即服务:揭秘"企鹅"组织如何将全球诈骗产业化
- EDRStartupHinder可阻断Windows 11启动时的杀毒软件与EDR服务
- Instagram确认系统未遭入侵,1700万用户数据泄露实为旧数据翻新
- Everest黑客组织宣称入侵日产汽车公司
- 【安全圈】Everest黑客组织宣称入侵日产汽车公司
- 【安全圈】FBI 警告:朝鲜黑客正将恶意 QR 码用于鱼叉式网络钓鱼
- 【安全圈】MuddyWater 黑客组织通过鱼叉式钓鱼向中东多部门传播 RustyWater 远程木马
- 【安全圈】新型网络犯罪工具 ErrTraffic 实现 ClickFix 攻击自动化 伪造网站故障诱骗用户中招
- CCRC-DSO 数据安全官证书开课倒计时!
- GuidePoint Security
- Horizon3.ai
- Cerbero Blog
- VMRay
- Bug Bounty in InfoSec Write-ups on Medium
- From Failure to $32,000: My Bug Bounty Journey
- This Endpoint Was “Read-Only” — Until I Read Everything
- The Dark Web Dump Was Old — The Vulnerability Wasn’t ️
- How I Discovered Client-Side Desync (HTTP Request Smuggling) in Bug Bounty and Got Rewarded
- How Playing CTFs Taught Me to Think Like a Hacker
- How I Became the 4th Top Bug Bounty Researcher on Comolho: My Journey
- The €400 Bug - VPN/Geo Location Bypass
- Malwarebytes
- Received an Instagram password reset email? Here’s what you need to know
- Regulators around the world are scrutinizing Grok over sexual deepfakes
- Celebrating reviews and recognitions for Malwarebytes in 2025
- A week in security (January 5 – January 11)
- Enshittification is ruining everything online (Lock and Code S07E01)
- Intigriti
- 奇客Solidot–传递最新科技情报
- 安全分析与研究
- 漕河泾小黑屋
- 黑鸟
- 微步在线研究响应中心
- 代码卫士
- 安全内参
- 安全客
- 青衣十三楼飞花堂
- 二道情报贩子
- 看雪学苑
- 奇安信 CERT
- CT Stack 安全社区
- 漏洞推送
- 信息安全国家工程研究中心
- 中国信息安全
- 安全圈
- 安全牛
- 慢雾科技
- 极客公园
- 嘶吼专业版
- 数世咨询
- 黑伞安全
- 阿里安全响应中心
- 威胁猎人Threat Hunter
- 复旦白泽战队
- 字节跳动技术团队
- 情报分析师
- Over Security - Cybersecurity news aggregator
- The Alliance That Never Was: A Critical Analysis of the Ransomware “Alliance” Announced by Stormous
- Hacker gets seven years for breaching Rotterdam and Antwerp ports
- Facebook login thieves now using browser-in-browser trick
- Internet monitoring experts say Iran blackout likely to continue
- Assemblea dei Soci 2026
- Armenia probes alleged sale of 8 million government records on hacker forum
- CISA orders feds to patch Gogs RCE flaw exploited in zero-day attacks
- Hungary grants asylum to former Polish minister implicated in spyware probe
- 'Bad actor' hijacks Apex Legends characters in live matches
- Sweden detains ex-military IT consultant suspected of spying for Russia
- University of Hawaii Cancer Center hit by ransomware attack
- Fintech firm Betterment confirms data breach after hackers send fake crypto scam notification to users
- Target's dev server offline after hackers claim to steal source code
- Apple confirms Google Gemini will power Siri, says privacy remains a priority
- Ispezioni NIS2: come funzionano e quali responsabilità ricadono sulle organizzazioni
- Hidden Telegram proxy links can reveal your IP address in one click
- Microsoft is retiring the Lens scanner app for iOS, Android
- Spanish energy giant Endesa discloses data breach affecting customers
- Cos’è la guerra cognitiva e qual è la posizione della NATO
- Raccolta dati e AI, come informare correttamente gli interessati: le raccomandazioni
- Dutch court sentences hacker who used port systems to smuggle cocaine to 7 years
- Prevent cloud data leaks with Microsoft 365 access reviews
- Black Axe, arrestati oltre trenta individui legati alla cybergang
- UK launches formal investigation into X over ‘nudification’ of children images
- Max severity Ni8mare flaw impacts nearly 60,000 n8n instances
- Il caso OVH, quando il Canada sfida la sovranità digitale UE: i rischi per i nostri dati
- Gestire il rischio cyber dei sistemi di AI: le prime indicazioni operative del NIST
- Anthropic brings Claude to healthcare with HIPAA-ready Enterprise tools
- CERT-AGID 3-9 gennaio: phishing e malware aprono il 2026
- 安全419
- Arturo Di Corinto
- IT Service Management News
- 360数字安全
- 迪哥讲事
- 安全行者老霍
- Securityinfo.it
- Krypt3ia
- ICT Security Magazine
- SEI Blog
- CNVD漏洞平台
- Schneier on Security
- SANS Internet Storm Center, InfoCON: green
- NetSPI
- Dark Space Blogspot
- Security Affairs
- U.S. CISA adds a flaw in Gogs to its Known Exploited Vulnerabilities catalog
- Meta fixes Instagram password reset flaw, denies data breach
- Europol and Spanish Police arrest 34 in crackdown on Black Axe criminal network
- Credential-harvesting attacks by APT28 hit Turkish, European, and Central Asian organizations
- TorrentFreak
- The Hacker News
- n8n Supply Chain Attack Abuses Community Nodes to Steal OAuth Tokens
- ⚡ Weekly Recap: AI Automation Exploits, Telecom Espionage, Prompt Poaching & More
- GoBruteforcer Botnet Targets Crypto Project Databases by Exploiting Weak Credentials
- Anthropic Launches Claude AI for Healthcare with Secure Health Record Access
- Researchers Uncover Service Providers Fueling Industrial-Scale Pig Butchering Fraud
- Trend Micro Research, News and Perspectives
- The Register - Security
- No fire sale for firewalls as memory shortages could push prices higher
- 'Violence-as-a-service' suspect arrested in Iraq, extradition underway
- Businesses in 2026: Maybe we should finally look into that AI security stuff
- Block CISO: We red-teamed our own AI agent to run an infostealer on an employee laptop
- Infamous BreachForums forum breached, spilling data on 325K users
- Ofcom officially investigating X as Grok's nudify button stays switched on
- Tories vow to boot under-16s off social media and ban phones in schools
- India’s government denies it plans to demand smartphone source code
- Malaysia and Indonesia block X over failure to curb deepfake smut
- Instapaper: Unread
- The Shift from Disk Imaging to Digital Triage
- Contrasto al cyber crime, l’impegno della Polizia Postale nel 2025. Il report
- Language models cannot reliably distinguish belief from knowledge and fact | Nature Machine Intelligence
- Instagram denies breach amid claims of 17 million account data leak
- A massive breach exposed data of 17.5M Instagram users
- Con la multa a Cloudflare Piracy Shield dimostra ciò che sappiamo da tempo. Che non funziona
- Security Weekly Podcast Network (Audio)